Vulnerabilities
8 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-19660 | Cross Site Scripting (XSS) pandao editor.md 1.5.0 allows attackers to execute arbitrary code via crafted linked url values. Cross Site Scripting (XSS) pandao editor.md 1.5.0 allows attackers to execute arbitrary code via crafted linked url values. NVD description · AI analysis pending | 6.1 | <1% |
| — | ||
| CVE-2023-29641 | Cross Site Scripting (XSS) vulnerability in pandao editor.md thru 1.5.0 allows attackers to inject arbitrary web script or HTML via crafted markdown text. Cross Site Scripting (XSS) vulnerability in pandao editor.md thru 1.5.0 allows attackers to inject arbitrary web script or HTML via crafted markdown text. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2020-19698 +1 in the same advisory: …19697 | Cross Site Scripting vulnerability found in Pandao Editor.md v.1.5.0 allows a remote attacker to execute arbitrary code via a crafted script to the editor param Cross Site Scripting vulnerability found in Pandao Editor.md v.1.5.0 allows a remote attacker to execute arbitrary code via a crafted script to the editor parameter. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2019-14653 | pandao Editor.md 1.5.0 allows XSS via an attribute of an ABBR or SUP element. pandao Editor.md 1.5.0 allows XSS via an attribute of an ABBR or SUP element. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2019-9737 | Editor.md 1.5.0 has DOM-based XSS via vectors involving the '<EMBED SRC="data:image/svg+xml' substring. Editor.md 1.5.0 has DOM-based XSS via vectors involving the '<EMBED SRC="data:image/svg+xml' substring. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2018-19056 | pandao Editor.md 1.5.0 has DOM XSS via input starting with a "<<" substring, which is mishandled during construction of an A element. pandao Editor.md 1.5.0 has DOM XSS via input starting with a "<<" substring, which is mishandled during construction of an A element. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2018-16330 | Pandao Editor.md 1.5.0 allows XSS via crafted attributes of an invalid IMG element. Pandao Editor.md 1.5.0 allows XSS via crafted attributes of an invalid IMG element. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — |